CyberRota Analysis
AI-GeneratedOpenChoreo versions prior to 1.0.3, 1.1.3, and 1.2.0-rc.2 expose sensitive API endpoints without proper authentication, allowing unauthorized access to Kubernetes Secrets, the ability to mutate workloads, and execute commands across data planes. This critical vulnerability poses a significant risk to any organization using affected versions of OpenChoreo for Kubernetes, and immediate upgrades to the patched versions are essential to mitigate potential exploitation. Kubernetes administrators and security teams should prioritize this update to protect their environments from unauthorized access and potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.